fedora-selinux / selinux-policy

selinux-policy for Fedora is a large patch off the mainline
GNU General Public License v2.0
156 stars 157 forks source link

Allow dhcpcd the kill capability #2200

Closed zpytela closed 4 days ago

zpytela commented 5 days ago

The commit addresses the following AVC denial: type=PROCTITLE msg=audit(27.6.2024 18:45:35.616:596) : proctitle=dhcpcd -k type=AVC msg=audit(06/27/24 18:45:35.616:596) : avc: denied { kill } for pid=2677 comm=dhcpcd capability=kill scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=capability permissive=0 type=SYSCALL msg=audit(06/27/24 18:45:35.616:596) : arch=x86_64 syscall=kill success=no exit=EPERM(Operation not permitted) a0=0xa50 a1=SIGALRM a2=0x0 a3=0x4000 items=0 ppid=1941 pid=2677 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=5 comm=dhcpcd exe=/usr/sbin/dhcpcd subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null)

Resolves: rhbz#2294614